How to deal with a “Hacked” Windows computer

How to deal with a “Hacked” Windows computer

As a computer consultant or IT Manager you will encounter many instances of dealing with a “hacked” computer (or a suspected “hacked” computer.) If it is proven that the computer has been “hacked” or acting suspiciously, I generally recommend that the client rebuild the computer. The amount of work to clean the computer is extensive and a highly skilled process. Most clients are unaware of the amount of labor required to clean a computer. 

In most cases, the client will still opt for the cleaning, and that is when I need to inform them of the many steps required to carry out the request of cleaning their computer(s). 

No alt text provided for this image

Step 1: prepare for the cleaning of the computer by:

  1. Kill all non-essential processes using rkill. TDSSKiller and ProcessKiller.
  2. Run McAfee Stinger
  3. Do a FULL registry backup
  4. Do a full WMI repair
  5. Do a sysrestore clean
  6. Do a VSS set purge (Microsoft Volume Shadow Copy Service (VSS) snapshots) of the oldest set
  7. Create a system restore point
  8. Do a full SMART disk check (all disks)
  9. Set system time via NTP time

Congratulations, step one is complete, only 8 more steps to go!!

Step 2: Temp File Clean

  1. Clean the computer by running Tempclean: TempFileCleanup, CCLeaner, and BleachBit
  2. Backup & clear event logs
  3. Do a full Windows Update cache cleanup, 
  4. Do a full Internet Explorer cleanup 
  5. Do a full USB device cleanup

Step 3: DeBloat

  1. Remove all OEM bloatware

Step 4: DisInfect

  1. Run Kaspersky Virus Removal Tool 
  2. Run Sophos Virus Removal Tool 
  3. Run Malwarebytes
  4. Do a full DISM image check (Win8/2012 only)

Step 5: Repair

  1. Do a full Registry permissions reset
  2. Do a Filesystem permissions reset 
  3. Do a full SFC /scannow, SFC = Microsoft System File Checker
  4. Do a chkdsk (if necessary) on all drives

Step 6: Patch

  1. Update all Windows Software (7-Zip, Java, and Adobe Flash/Reader, etc.)
  2. Upgrade all of Windows Operating System 

Step 7 Optimize: 

  1. Do a page file reset 
  2. defrag %SystemDrive% (usually C: and not required drive is an SSD)

Step 8 Wrap-up: 

  1. Create and send a job completion report 

Step 9 Manual stuff: 

  1. Do a full rook kit scan (PCHunter)
  2. Do a full Adware scan (AdwCleaner, ComboFix, Junkware Removal Tool)
  3. Repair/relink all Services (ServicesRepair)
  4. MBR review (Master Boot Record) and a review of all startup commands
No alt text provided for this image

This is a good reasonable start and should clean/optimize the majority of cases encountered. One caveat is that I would recommend doing a FULL drive image backup of your client’s PC before starting. This is a lot of work and you will need a high level of skill to review any errors encountered and then take appropriate actions.

Now, what would say if I told you that you could automate the majority of these steps and processes?

The Reddit community (r/TronScript) has maintained an automated scripting tool to do all of the above steps and more. 

This is an integral collection of tools for anyone to keep on a USB flash drive (<700MB) and will prove extremely effective to repair and rid the most common issues that are making a windows computer perform poorly. It is not a quick fix so expect to spend a little time using it, but your client's machine is worth it!

Labour of Passion

Charles Duncan is a Veteran IT Consultant who founded Crown Computing Incorporated and managed Micro Services for York University. Charles has extensive experience in Linux, Apple, Windows, and Networking with a Bachelor of Science in Computer Science, and is also MCSE, and CCNA certified. Connect with Charles on LinkedIn and Facebook.

要查看或添加评论,请登录

Charles Duncan的更多文章

社区洞察

其他会员也浏览了